<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Stealthwatch Customer Community - SIEM Integration in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4621541#M793</link>
    <description>&lt;P&gt;What is the best method for getting security events and analytics into an external SIEM (Splunk)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;</description>
    <pubDate>Tue, 31 May 2022 13:47:47 GMT</pubDate>
    <dc:creator>philipmein</dc:creator>
    <dc:date>2022-05-31T13:47:47Z</dc:date>
    <item>
      <title>Stealthwatch Customer Community - SIEM Integration</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4621541#M793</link>
      <description>&lt;P&gt;What is the best method for getting security events and analytics into an external SIEM (Splunk)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 13:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4621541#M793</guid>
      <dc:creator>philipmein</dc:creator>
      <dc:date>2022-05-31T13:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Customer Community - SIEM Integration</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4666165#M849</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/88434"&gt;@philipmein&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This depends what kind of data you want to have in your SIEM.&lt;/P&gt;
&lt;P&gt;You can decide to just collect your flows with SNA and then forward the raw logs to your SIEM.&lt;BR /&gt;Or, you let SNA do all the magic it can do, you fine tune your use cases and then forward the security events to your SIEM.&lt;/P&gt;
&lt;P&gt;Anyway, the best thing is to do this by syslog and, as you're using Splunk, make sure to also install the Cisco Secure Analytics (maybe it's also called Stealthwatch) App to get some nice visuals in Splunk, too!&lt;/P&gt;
&lt;P&gt;How you can send it to your SIEM you should find in the documentation. Search for the "System Configuration Guide", here is a sample for v7.3.1 &lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/SW_7_3_2_System_Configuration_Guide_DV_1_1.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/SW_7_3_2_System_Configuration_Guide_DV_1_1.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps, cheers, another Philipp&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2022 08:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4666165#M849</guid>
      <dc:creator>Philipp Tannich</dc:creator>
      <dc:date>2022-08-09T08:17:50Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Customer Community - SIEM Integration</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4996742#M1022</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1060594"&gt;@Philipp Tannich&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;is there any updated link?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 12:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4996742#M1022</guid>
      <dc:creator>aqulle</dc:creator>
      <dc:date>2024-01-15T12:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: Stealthwatch Customer Community - SIEM Integration</title>
      <link>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4996747#M1023</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1020289"&gt;@aqulle&lt;/a&gt;,&amp;nbsp;there is one for 7.4.2: &lt;A href="https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/7_4_2_System_Configuration_Guide_DV_1_2.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/td/docs/security/stealthwatch/system_installation_configuration/7_4_2_System_Configuration_Guide_DV_1_2.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;BUT, if you want, you can also get the data out also with API calls like you can see here: &lt;A href="https://developer.cisco.com/docs/stealthwatch/enterprise/" target="_blank"&gt;https://developer.cisco.com/docs/stealthwatch/enterprise/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps!&lt;BR /&gt;Best, Philipp&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 12:16:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/stealthwatch-customer-community-siem-integration/m-p/4996747#M1023</guid>
      <dc:creator>Philipp Tannich</dc:creator>
      <dc:date>2024-01-15T12:16:41Z</dc:date>
    </item>
  </channel>
</rss>

